using-git-worktrees
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill attempts to read configuration preferences from a local file (
CLAUDE.md) usinggrepand instructs the agent to use the found value without further verification. - Ingestion points: The
CLAUDE.mdfile (Step 2) is read to determine the worktree directory path. - Boundary markers: None. The agent is instructed to use the preference "without asking."
- Capability inventory: The skill possesses the ability to execute shell commands (
git,mkdir,echo), write to files (.gitignore), and install software packages. - Sanitization: No sanitization or validation of the input retrieved from
CLAUDE.mdis specified before it is used in subsequent shell commands. - [COMMAND_EXECUTION]: The skill automatically executes build and installation scripts based on the presence of project files.
- Evidence: The "Post-Creation Setup" section automatically triggers
npm install,cargo build,pip install,poetry install, andnpm testbased on the existence ofpackage.json,Cargo.toml, orrequirements.txt. - Risk: This executes code (install scripts or test suites) defined within the repository being worked on.
- [EXTERNAL_DOWNLOADS]: The skill triggers the retrieval of external dependencies from public registries.
- Evidence: Commands like
npm install,go mod download, andpoetry installfetch packages from external sources (npm, PyPI, Go Proxy, etc.) during the worktree setup process.
Audit Metadata